# Unable to test output with Filebeat to Elasticsearch

**URL:** <https://discuss.elastic.co/t/unable-to-test-output-with-filebeat-to-elasticsearch/282654>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 27, 2021, 9:54am UTC](https://discuss.elastic.co/t/unable-to-test-output-with-filebeat-to-elasticsearch/282654 "2021-08-27T09:54:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jhaos](https://avatars.discourse-cdn.com/v4/letter/j/3bc359/32.png) [@jhaos](https://discuss.elastic.co/u/jhaos)\
**Post date:** [August 27, 2021, 9:54am UTC](https://discuss.elastic.co/t/unable-to-test-output-with-filebeat-to-elasticsearch/282654/1 "2021-08-27T09:54:53Z")

</div>

Hi there, I'm trying to send the logs from Filebeat to Elasticsearch but I'm stuck with a problem regarding credentials or certification.

I have the following configuration in filebeat.yml

```auto
    filebeat.modules:
      - module: my_module
        alerts:
          enabled: true
        archives:
          enabled: false
    output.elasticsearch:
      hosts: ['my_elastic:9200']
      protocol: https
      user: "${FILEBEAT_KS_USER}"
      password: "${FILEBEAT_KS_PASS}"
      ssl.enable: true
      ssl.verification_mode: full
      ssl.certificate_authorities: ["/usr/share/filebeat/config/<ca_chain_cert>"]
      ssl.certificate: "/usr/share/filebeat/config/ssl/certs/filebeat-access.pem"
      ssl.key: "/usr/share/filebeat/config/ssl/private/filebeat-access.key"
      ssl.key_passphrase: "${KEYPASSPHRASE}"

```

When I try filebeat test output I'm receiving the next output:

```auto
# filebeat test output
elasticsearch: https://my_elastic:9200...
  parse url... OK
  connection...
    parse host... OK
    dns lookup... OK
    addresses: 172.20.106.184
    dial up... OK
  TLS...
    security: server's certificate chain verification is enabled
    handshake... OK
    TLS version: TLSv1.3
    dial up... OK
  talk to server... ERROR 401 Unauthorized: Unauthorized

```

Receiving similar logs in elasticsearch

```auto
[2021-08-27T09:58:12,303][WARN][c.a.o.s.h.HTTPBasicAuthenticator] [odfe-0] Invalid 'Authorization' header, send 401 and 'WWW-Authenticate Basic'
[2021-08-27T09:58:20,450][WARN][c.a.o.s.h.HTTPBasicAuthenticator] [odfe-0] Invalid 'Authorization' header, send 401 and 'WWW-Authenticate Basic'

```

I've followed [Connect filebeat to elasticsearch - #2 by pierhugues](https://discuss.elastic.co/t/connect-filebeat-to-elasticsearch/150240/2) and made the workaround to avoid the error explained in this post.

I've tried to harcode the user and password using the elastic credentials and it didn't work but I'm able to make curls with both users, elastic and filebeat successfully but still receiving the authentication error.

Any ideas? Please help

Thanks

---

<div class="post-metadata">

**Author:** ![jhaos](https://avatars.discourse-cdn.com/v4/letter/j/3bc359/32.png) [@jhaos](https://discuss.elastic.co/u/jhaos)\
**Post date:** [September 6, 2021, 9:38am UTC](https://discuss.elastic.co/t/unable-to-test-output-with-filebeat-to-elasticsearch/282654/2 "2021-09-06T09:38:56Z")

</div>

Anyone can advise, please?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2021, 11:39am UTC](https://discuss.elastic.co/t/unable-to-test-output-with-filebeat-to-elasticsearch/282654/3 "2021-10-04T11:39:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
